Privacy Policy
This Privacy Policy explains how the operator of our online platform collects, uses, stores, discloses, and protects personal data when providing subscription management services, including recurring payment processing, customer billing solutions, and automated payment reminders.
This service is intended primarily for businesses. Businesses using the service may upload or otherwise process information relating to their customers, subscribers, employees, or other individuals. Where we process personal data on behalf of a business customer, that business generally determines the purposes and means of processing, and its own privacy notice may also apply.
Who We Are
For personal data that we process for our own business purposes, the service operator is responsible for determining how and why the data is used. Our physical address is:
Labrador Villa RoadSingapore 119189
Singapore
Personal Data We Collect
Depending on how the service is used, we may collect the following categories of personal data:
- Account and business information, such as names, job titles, organisation details, account credentials, and billing contacts.
- Subscriber and customer information entered by business customers, such as names, postal addresses, subscription details, billing status, payment schedules, and transaction history.
- Payment-related information, such as payment tokens, transaction references, payment status, currency, and limited payment instrument details provided by payment providers.
- Usage and technical information, such as IP address, browser type, device information, access times, log data, and interactions with the platform.
- Information provided when individuals request support, exercise privacy rights, or otherwise interact with the service.
How We Use Personal Data
We use personal data only for appropriate and lawful purposes, including:
- Providing, operating, maintaining, and securing subscription and billing features.
- Processing recurring payments and maintaining accurate transaction records through authorised payment providers.
- Sending payment reminders, service notices, administrative messages, and other communications necessary to provide the service.
- Authenticating users, preventing fraud, detecting misuse, and protecting the rights, property, and security of the service and its users.
- Improving performance, reliability, usability, and functionality through aggregated or appropriately protected analysis.
- Meeting legal, regulatory, accounting, tax, and dispute-resolution obligations.
Lawful Bases for Processing
Where the GDPR applies, we rely on one or more lawful bases, including performance of a contract, compliance with legal obligations, our legitimate interests in operating and securing the service, and consent where consent is required. Where processing is performed for a business customer, that customer is responsible for identifying the appropriate lawful basis and providing required notices and instructions.
Payment Information
Payment card details and other sensitive payment credentials are generally collected and processed by authorised payment service providers rather than stored directly by our platform. We may receive tokens, transaction identifiers, payment status, and limited payment details necessary to manage subscriptions, reconcile transactions, prevent fraud, and provide billing records. Payment providers process personal data under their own terms and privacy notices.
Cookies and Similar Technologies
Our online platform may use essential cookies and similar technologies to maintain sessions, remember security settings, support functionality, and understand service performance. Where required by law, non-essential technologies will be used only with appropriate consent. Cookie choices may affect the availability of certain features.
Disclosure of Personal Data
We may disclose personal data to carefully selected recipients when necessary and lawful, including:
- Payment processors, financial institutions, fraud-prevention providers, and billing infrastructure providers.
- Hosting, storage, analytics, security, customer support, and other technology service providers acting under appropriate contractual obligations.
- Professional advisers, auditors, insurers, regulators, law-enforcement authorities, courts, or other parties where disclosure is required or permitted by law.
- A successor or transaction party in connection with a merger, acquisition, restructuring, financing, or sale of assets, subject to appropriate safeguards.
International Data Transfers
Some service providers may process personal data outside Singapore or the country where it was collected. When required, we use legally recognised safeguards, such as contractual protections, adequacy decisions, approved transfer mechanisms, or other measures required under applicable data protection law.
Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including to provide the service, maintain business and financial records, resolve disputes, enforce agreements, prevent fraud, and meet legal obligations. Retention periods may vary according to the type of data, the nature of the relationship, and applicable legal requirements. Data is securely deleted or anonymised when it is no longer required.
Security
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, misuse, and destruction. No method of transmission or storage is completely secure, and users should protect their account credentials and notify the relevant business administrator promptly of suspected unauthorised activity.
Your Privacy Rights
Subject to applicable law, individuals may have the right to:
- Request access to personal data and information about how it is processed.
- Request correction of inaccurate or incomplete personal data.
- Request deletion, restriction, or cessation of processing in appropriate circumstances.
- Object to processing based on legitimate interests or direct marketing, where applicable.
- Request portability of certain personal data processed by automated means.
- Withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.
- Lodge a complaint with the applicable data protection authority.
Requests should include enough information to verify identity and locate the relevant records. Individuals whose data is processed through a business customer should generally direct requests to that business first. We may refuse or limit a request where permitted by law, and we will explain the reason where appropriate.
Children’s Data
The service is designed for business use and is not directed to children. We do not knowingly collect personal data from children in violation of applicable law. If a business customer believes that a child’s data has been provided unlawfully, it should arrange for the data to be removed where appropriate.
Changes to This Policy
We may update this Privacy Policy to reflect changes in the service, legal requirements, or our data practices. The revised policy will be posted through our online platform, and material changes will be communicated through appropriate service channels where required.
Privacy Enquiries
Written privacy enquiries and requests may be sent to:
Labrador Villa RoadSingapore 119189
Singapore